What's New in 2.14.0
Version 2.14.0 introduces significant improvements to Ransomware Defender, focusing on reducing alert fatigue and improving the accuracy of ransomware detection through intelligent application behavior learning.
Application Fingerprinting
Application Fingerprinting is a new feature that identifies normal application behavior patterns and automatically suppresses alerts that match known safe behavior. This capability addresses one of the most critical challenges faced by storage administrators: alert fatigue caused by repeated false positives.
Key Benefits:
- Reduced Alert Fatigue: Automatically suppress alerts from known safe application behavior
- Improved Detection Accuracy: Focus on genuine threats rather than false positives
- Quick Results: Leverage existing false positive data from Threat Analyzer to deliver immediate value after upgrade
- Maintained Protection: Continue protecting against ransomware while reducing noise
- Seamless Integration: Works with existing GUI and APIs for an improved user experience
Application Fingerprinting Learning Management
Application Fingerprinting is designed to deliver rapid time-to-value by leveraging existing data already collected in Threat Analyzer. This enables quick results after upgrading to version 2.14.0.
Post-Upgrade Recommendation: Upload Historical Events
To maximize the effectiveness of Application Fingerprinting, upload historical events to the AFP database after upgrading. This step ensures AFP can learn from your past environment and deliver more accurate results faster.
- Manually upload historical events using the process described below
- Optionally filter out events you do not want included before uploading
This step is especially important because:
- It accelerates the learning process by incorporating past events
- In Monitor Mode (with learning disabled), events are automatically closed as unresolved
- Unresolved events are not learned by the AFP database
- Environments that do not mark events as false positives will not benefit from automatic learning without this upload
By uploading historical events, AFP builds a more complete baseline and improves detection accuracy sooner. For the exact steps, see Application Fingerprinting Learning Management.